Official-source education
NZ Post parcel SMS phishing
In its 30 July 2026 example, NZ Post warned about SMS phishing messages using its brand and a link to prompt people to click or submit a form. NZ Post advises people not to click the link or submit a form.
Risk level:highEvidence:NZ Post has issued a clear warning.
First observed:30 July 2026
Last verified:4 August 2026
Impersonated entities:NZ Post
Channels:SMS
Target groups:People expecting parcels or using NZ Post services
Common behaviour or wording
- The SMS uses the NZ Post brand and includes a link.
- It prompts the recipient to click the link or submit a form.
Information or funds requested
- Personal or payment information may be requested through a web form
Key risk indicators
- The link is not nzpost.co.nz or an NZ Post nzp.st short link.
- The message asks you to submit a form through its link.
- NZ Post says it will not ask for usernames, passwords, credit-card or account information by text or email.
What to do
- Do not click the SMS link or submit a form.
- Forward a suspicious text to DIA on 7726, free of charge.
- If you need to check a parcel, go to the NZ Post website or use its official contact channels yourself.
- If you entered card or account details, contact your bank immediately.
Official reporting channels
- DIA: forward suspicious SMS to 7726
- NZ Post official support or Security contact
Official sources
- NZ Post · 30 July 2026: SMS phishing scam30 July 2026
Timeline
- 30 July 2026 NZ Post published its SMS phishing-scam example.
- 4 August 2026 NZSAFE manually verified that the official page remained accessible.
Variants
- Parcel, redelivery, or update-details messages should be checked independently through the NZ Post website.